Privacy Policy

Last updated: 7 September 2026

This Privacy Policy explains how Shira (“Shira”, “we”, “us”) collects, uses, shares, and protects personal information across the Shira website (getshira.com), the merchant portal, merchant storefronts, and the Shira merchant mobile app (together, the “Services”). By using the Services you agree to this policy.

Who we are

Shira is an e-commerce platform that lets merchants in the Syrian and Arab market create an online store and receive orders. Depending on how you use the Services, you may be a merchant (store owner or staff) or a customer buying from a merchant’s storefront. For questions about this policy, contact us at [email protected].

Information we collect

We collect the following, depending on how you use the Services:

  • Account information: your name, email address, and phone number (used to sign in via a one-time code).
  • Merchant / store information: store name, contact details, business information, and the payment and shipping settings you enter.
  • Order and customer information: when a customer places an order on a merchant storefront we receive the name, phone number, delivery address, and order contents.
  • Payment information: processed by our payment providers; we do not store full card numbers. Cash-on-delivery and bank or wallet transfers are recorded only as the chosen method.
  • Mobile app and device data: device model, operating system, app version, and a push-notification token. Biometric unlock (Face ID / fingerprint) is handled by your device and is never transmitted to us.
  • Content you provide: product images you upload from your camera or photo library, only when you choose to.
  • Usage and technical data: IP address, pages viewed, a first-party storefront visitor identifier for basic analytics, cookies needed to sign in, a campaign attribution cookie on our marketing website, advertising cookies set by the Meta pixel and analytics cookies set by Google Analytics on that website, and diagnostic and error data.

How we use your information

  • Provide and operate the Services: accounts, storefronts, orders, and the mobile app.
  • Authenticate you with one-time codes, keep accounts secure, and prevent fraud and abuse.
  • Send the transactional messages you would expect (sign-in codes, order confirmations, and order alerts) by email, push notification, and, where available, SMS.
  • Process payments and support order fulfilment and delivery.
  • Maintain, troubleshoot, and improve the Services using diagnostics and aggregate analytics.
  • Measure and improve our own marketing: understand which campaigns and links bring merchants to Shira, and measure and optimise the advertising we run.
  • Comply with legal, tax, and accounting obligations.

How we share information

We do not sell your personal data. We share information only as follows:

  • Between a merchant and their customer: completing an order shares the customer’s contact and delivery details with that merchant, and the merchant’s contact details with the customer, so the order can be fulfilled.
  • Service providers acting on our behalf: payment processing (Paymera and the other methods a merchant enables), transactional email (Amazon SES), hosting and network security (Hetzner in Germany, and Cloudflare), error monitoring (Sentry), and push-notification delivery (Expo, Apple APNs, and Google FCM). The app stores (Apple App Store and Google Play) process app downloads and updates.
  • Advertising measurement: on our marketing website getshira.com, the Meta pixel reports to Meta Platforms that a page was viewed, and, on the pricing page, that a plan button was pressed together with which plan it was, so that we can measure and optimise our own advertising. On the same website, Google Analytics reports to Google which page was viewed and which campaign or advertisement the visit came from, so that we can tell which of our advertising sources bring merchants to Shira. See “Cookies and similar technologies” below.
  • Legal and safety: when required by applicable law, or to protect the rights, property, or safety of Shira, our users, or the public.

Where your data is stored

Our servers are hosted in Germany (European Union), with encrypted backups on Cloudflare’s network. If you access the Services from Syria or another country, your information may be processed and stored outside your country of residence.

Transfers outside the EEA. Three recipients process data outside the European Economic Area: Meta Platforms Ireland, which operates the advertising pixel on getshira.com and transfers to Meta Platforms, Inc. in the United States under the EU–US Data Privacy Framework and the European Commission’s standard contractual clauses; Google Ireland Limited, which operates Google Analytics on getshira.com and transfers to Google LLC in the United States on the same basis; and the app stores and push services (Apple, Google, Expo) that deliver our mobile app and its notifications, on the same clauses. Where you are in the EEA, the United Kingdom, or Switzerland, our legal basis for the advertising pixel, Google Analytics and the campaign attribution cookie is your consent, which you give or refuse in the cookie banner and can withdraw at any time; for everything else it is the performance of our contract with you and our legitimate interest in running and securing the Services.

Data retention

We keep account and order data for as long as your account is active and as needed to provide the Services. Some records, such as order and transaction history, may be retained after an account is closed where needed to meet legal, tax, accounting, or dispute-resolution obligations, after which they are deleted or anonymised.

Your rights and choices

  • Access and correct: view and update most of your account information directly in the portal or the mobile app.
  • Delete: request deletion of your account and associated personal data from Account → Security in the app, or by contacting [email protected]. Some records may be retained where the law requires.
  • Notifications: turn off non-essential push notifications in the app’s notification settings; essential messages such as sign-in codes are required to use the Services.

Security

We protect your data with encryption in transit (HTTPS/TLS), strict isolation between merchants, and access controls. No method of transmission or storage is completely secure, but we work to protect your information and to address any issues promptly.

Cookies and similar technologies

Essential. Cookies needed to sign you in and keep your session. These cannot be turned off, and blocking them will stop you signing in.

Our own analytics and attribution. A first-party identifier that lets a merchant see basic, aggregate visitor analytics for their storefront. Separately, on our marketing website getshira.com, a cookie named shira_attr records which campaign or link brought you to us, so we can tell which advertising actually works. It lasts 90 days, can be read only by our servers, and contains no name, email address, or phone number.

Website analytics, without cookies. On our marketing website we run Umami, an analytics tool we host ourselves, on our own server, under an analytics subdomain of this site. The data is not shared with an analytics company and it adds no recipient to the transfers described above; like every other page here, the request passes through Cloudflare, which we already name above as our hosting and network-security provider. Umami sets no cookie and stores no identifier on your device. What it records for each visit is the page address, the link that referred you, your screen size, your language, and the country your IP address resolves to. Your IP address itself is not stored: it is combined with your browser type and a secret that changes every month into a one-way fingerprint that groups the pages of a single visit together, and because that secret rotates, visits cannot be followed from one month to the next. Campaign parameters are stripped before the page address is stored, so an advertising click identifier is never kept alongside it. We also record which of a small number of actions were taken on a page, such as opening a question or pressing a pricing button, so we can tell which parts of the site are useful. Because none of this is stored on your device it runs without asking, but it honours the “Do Not Track” setting in your browser: switch that on and nothing about your visit is recorded, and the request for the analytics file itself is excluded from our server logs. One note for completeness: because the analytics subdomain is part of this site, your browser attaches the shira_attr attribution cookie described above to requests for it. Umami never reads it.

Third-party advertising. On our marketing website getshira.com only, we run the Meta (Facebook) pixel. It sets its own cookies, including _fbp, and tells Meta that a page was viewed, and on the pricing page that a plan button was pressed together with which plan it was, so that we can measure our advertising and Meta can optimise how it is delivered. We do not send Meta your name, email address, or phone number, and we do not use advanced matching. The pixel does not run on merchant storefronts or in our mobile apps.

Third-party analytics. On our marketing website getshira.com only, we also run Google Analytics. It sets its own cookies, including _ga, and tells Google which pages were viewed and which campaign, advertisement or link the visit came from, so that we can tell which of our advertising sources bring merchants to Shira. We do not send Google your name, email address, or phone number, we do not link it to an account, and we have switched off Google signals and advertising personalisation, so it is not used to build an advertising profile of you or to follow you across devices. It does not run on merchant storefronts or in our mobile apps.

Asking first, and where. If you are visiting getshira.com from the European Economic Area, the United Kingdom, or Switzerland, we ask before setting the attribution cookie or loading the Meta pixel or Google Analytics: until you accept, none of them happens. Your choice is remembered for a year, declining is a real choice rather than a delay, and you can change it at any time from the cookie control at the bottom of the page. To be exact about the limit of that promise: it covers this marketing website. Merchant storefronts serve customers in Syria, which has no cookie-consent regime, and they set the first-party visitor identifier described above without a banner. A merchant who switches on their own advertising or analytics tag on their storefront chooses that themselves and is responsible for consent in the markets they sell to.

You can clear or block cookies in your browser settings, you can control how Meta uses your activity in your Meta account settings or through the advertising controls in your browser or device, and you can stop Google Analytics in every website with Google’s browser opt-out add-on.

Children

The Services are intended for merchants and adult customers and are not directed to children under 13. We do not knowingly collect personal information from children; if you believe a child has provided us with data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date above; we may also communicate significant changes in the app or by email.

Contact us

For any question or request about this policy or your personal data, contact us at [email protected].